Security & Trust

Your data stays
yours. Always.

MycoFarm is built on a foundation of end-to-end encryption, on-site deployment options, and independently audited controls — so your grow data never leaves your control.

Request a demo Report a vulnerability
ENCRYPTIONAES-256 AT REST✓ ACTIVE
TLS1.3 IN TRANSIT✓ ENFORCED
SOC 2TYPE II✓ CERTIFIED
UPTIME99.98%↑ 12 MO AVG
VULN SCANCONTINUOUS✓ CLEAN
PENTESTANNUAL✓ PASSED
MFAALL ACCOUNTS✓ REQUIRED
GDPR / PIPEDACOMPLIANT✓ VERIFIED
ENCRYPTIONAES-256 AT REST✓ ACTIVE
TLS1.3 IN TRANSIT✓ ENFORCED
SOC 2TYPE II✓ CERTIFIED
UPTIME99.98%↑ 12 MO AVG
VULN SCANCONTINUOUS✓ CLEAN
PENTESTANNUAL✓ PASSED
MFAALL ACCOUNTS✓ REQUIRED
GDPR / PIPEDACOMPLIANT✓ VERIFIED
99.98%
Platform uptime over 12 months
256-bit
AES encryption for all data at rest
SOC 2
Type II certified, independently audited
<4hr
Incident response SLA for critical issues

Designed secure
from the substrate up

End-to-end encryption

All sensor telemetry, grow room data, and user records are encrypted with AES-256 at rest and TLS 1.3 in transit — from device edge to storage layer.

Data Protection

On-site deployment

Deploy the full MycoFarm stack inside your own network. No grow data — substrate logs, contamination flags, yield records — ever leaves your facility without explicit consent.

Data Sovereignty

Role-based access control

Granular RBAC with MFA enforced across all accounts. Assign growers, supervisors, and auditors exactly the permissions they need — no more, no less.

Identity

Continuous vulnerability scanning

Automated CVE scanning runs daily across all infrastructure. Critical findings trigger immediate remediation workflows with documented resolution timelines.

Monitoring

Immutable audit logs

Every action — configuration changes, alert acknowledgements, data exports — is logged with actor, timestamp, and context. Logs are tamper-proof and exportable for regulatory review.

Audit Trail

Incident response SLA

Defined response times for every severity tier: critical incidents are acknowledged within 1 hour, with status updates every 30 minutes until resolved.

Reliability

A layered defence model
across every grow room

MycoFarm applies defence-in-depth: each layer — network, application, data, and physical — is independently hardened so that a compromise at one layer does not cascade across your operation.

01

Network perimeter

Private VPC with strict ingress/egress rules, WAF, and DDoS mitigation on all public endpoints. No sensor data is routed over the public internet by default.

02

Application security

OWASP Top 10 remediation baked into our SDLC. All releases pass automated SAST, DAST, and dependency-check pipelines before deployment.

03

Data isolation

Each farm's data is logically isolated at the database level. Multi-tenant environments use row-level security; on-premise deployments are fully air-gapped by default.

04

Physical & edge security

On-site hardware ships pre-hardened with signed firmware, disabled unnecessary services, and automatic security patch delivery over an authenticated update channel.

MYCO
FARM
SECURE

Audit-ready by design,
not by afterthought

SOC 2 Type II

Independently audited security controls covering availability, confidentiality, and processing integrity — report available on request.

PIPEDA Compliant

Full alignment with Canada's Personal Information Protection and Electronic Documents Act for any data touching Canadian growers or consumers.

GDPR Ready

Data subject rights, lawful processing bases, and EU data residency options for operations exporting to European markets.

HACCP Documentation

Automated, tamper-proof logging of all critical control points — structured to satisfy CFIA, USDA, and EU food safety audit requirements.

Canada Organic Alignment

Input tracking and chain-of-custody records built to satisfy CGSB-32.310 and 32.311 audit requirements without manual paperwork.

Annual Penetration Tests

Third-party red-team exercises conducted annually. Findings and remediation timelines are shared with enterprise customers under NDA.

RBAC & Least Privilege

Granular access policies ensure team members see only the rooms, data sets, and controls appropriate to their role.

Data Retention Controls

Configurable retention policies let you define how long sensor, yield, and compliance records are kept — with automated purge or export on schedule.

We take every report
seriously and act fast

Report a vulnerability

If you discover a security issue in MycoFarm, we want to hear from you. Email us at security@mycofarm.io with a description of the issue, steps to reproduce, and any proof-of-concept.

We acknowledge all reports within 24 hours and commit to a full triage response within 5 business days. We do not pursue legal action against good-faith security researchers.

security@mycofarm.io

Incident response timeline

Our security team operates on clearly defined SLAs for every severity tier.

P0 — Critical

Acknowledge <1 hr · Resolve <4 hr

Active data breach or system compromise. Full incident team mobilised immediately.

P1 — High

Acknowledge <4 hr · Resolve <24 hr

Severe vulnerability with potential for exploitation. Patch released within one business day.

P2 — Medium

Acknowledge <24 hr · Resolve <7 days

Moderate risk without active exploitation. Addressed in the next scheduled release cycle.

P3 — Low

Acknowledge <5 days · Resolve next release

Informational findings and hardening opportunities. Tracked and resolved in quarterly cycles.

Have questions about
how we protect your data?

Our security team is available to walk enterprise customers through our controls, share audit reports, and scope custom deployment architectures.